{"id":176,"date":"2008-12-03T10:16:31","date_gmt":"2008-12-03T18:16:31","guid":{"rendered":"http:\/\/www.outflux.net\/blog\/?p=176"},"modified":"2008-12-03T10:16:49","modified_gmt":"2008-12-03T18:16:49","slug":"bogosec-run-on-intrepid-main","status":"publish","type":"post","link":"https:\/\/outflux.net\/blog\/archives\/2008\/12\/03\/bogosec-run-on-intrepid-main\/","title":{"rendered":"bogosec run on intrepid main"},"content":{"rendered":"<p>Care of Mike Owens and <a href=\"http:\/\/blog.dustinkirkland.com\/search\/label\/Ubuntu\">Dustin Kirkland<\/a>, <a href=\"https:\/\/launchpad.net\/ubuntu\/+source\/bogosec\">bogosec<\/a> has been uploaded to Jaunty (in the <a href=\"https:\/\/launchpad.net\/ubuntu\/jaunty\/+queue?queue_state=0&#038;queue_text=bogosec\">NEW queue<\/a> at the moment).  It is a source-code analyzer framework with plugins for <a href=\"http:\/\/lintian.debian.org\/\">lintian<\/a>, <a href=\"http:\/\/www.fortify.com\/security-resources\/rats.jsp\">rats<\/a>, and <a href=\"http:\/\/www.dwheeler.com\/flawfinder\/\">flawfinder<\/a>.  Out of curiousity, I <a href=\"http:\/\/people.ubuntu.com\/~kees\/bogosec\/\">ran it<\/a> on all of Intrepid main.  Highest 5 <a href=\"http:\/\/people.ubuntu.com\/~kees\/bogosec\/intrepid-main\/scores.txt\">scores<\/a> were:<\/p>\n<ol>\n<li>0.717338929043293 <a href=\"http:\/\/people.ubuntu.com\/~kees\/bogosec\/intrepid-main\/lsscsi\">lsscsi<\/a><\/li>\n<li>0.612729234088457 <a href=\"http:\/\/people.ubuntu.com\/~kees\/bogosec\/intrepid-main\/nevow\">nevow<\/a><\/li>\n<li>0.561151781356762 <a href=\"http:\/\/people.ubuntu.com\/~kees\/bogosec\/intrepid-main\/powertop\">powertop<\/a><\/li>\n<li>0.431034482758621 <a href=\"http:\/\/people.ubuntu.com\/~kees\/bogosec\/intrepid-main\/language-pack-tk-base\">language-pack-tk-base<\/a><\/li>\n<li>0.431034482758621 <a href=\"http:\/\/people.ubuntu.com\/~kees\/bogosec\/intrepid-main\/language-pack-se-base\">language-pack-se-base<\/a><\/li>\n<\/ol>\n<p>As Dustin reminded me, bogosec seems biased against smaller code bases.  In the case of the lang packs, the score is entirely from lintian.  Both lsscsi and powertop deal mostly with input from kernel strings, so while they scored highly, I doubt either is actually vulnerable to very much.  I haven&#8217;t looked at nevow yet.  Also, both rats and flawfinder yell about things that are mitigated by <a href=\"https:\/\/wiki.ubuntu.com\/CompilerFlags\">compiler flags<\/a> (e.g. -D_FORTIFY_SOURCE=2) so those warnings are less interesting too.<\/p>\n<p>Really, this all boils down to &#8220;we need better code analyzers&#8221;.  The best tool will be one that predicts CVE counts (I would expect the <a href=\"http:\/\/people.ubuntu.com\/~kees\/bogosec\/intrepid-main\/linux\">Linux kernel<\/a> to be at the top, since it has the all-time highest number of <a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvekey.cgi?keyword=linux+kernel\">CVEs filed against it<\/a>).<\/p>\n<p>To get closer to reality, I think just doing a normal package build and scanning for stderr output would be meaningful (gcc has plenty of built-in checks already).  Steve Beattie suggested writing a plugin for <a href=\"http:\/\/www.kernel.org\/pub\/software\/devel\/sparse\/\">sparse<\/a>, too.<\/p>\n<p style='text-align:left'>&copy; 2008, <a href=\"https:\/\/outflux.net\/blog\/\">Kees Cook<\/a>. This work is licensed under a <a rel=\"license\" href=\"http:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/\">Creative Commons Attribution-ShareAlike 4.0 License<\/a>.<br \/><a rel=\"license\" href=\"http:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/\"><img decoding=\"async\" alt=\"CC BY-SA 4.0\" style=\"border-width:0\" src=\"https:\/\/i.creativecommons.org\/l\/by-sa\/4.0\/88x31.png\" \/><\/a> <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Care of Mike Owens and Dustin Kirkland, bogosec has been uploaded to Jaunty (in the NEW queue at the moment). It is a source-code analyzer framework with plugins for lintian, rats, and flawfinder. Out of curiousity, I ran it on all of Intrepid main. Highest 5 scores were: 0.717338929043293 lsscsi 0.612729234088457 nevow 0.561151781356762 powertop 0.431034482758621 [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5,6,14,19],"tags":[],"_links":{"self":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts\/176"}],"collection":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/comments?post=176"}],"version-history":[{"count":0,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts\/176\/revisions"}],"wp:attachment":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/media?parent=176"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/categories?post=176"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/tags?post=176"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}